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DCID No. 1/16 


DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/16! 


ECURITY OF FOREIGN INTELLIGENCE IN AUTOMATED: 
DATA PROCESSING SYSTEMS AND NETWORKS 


(Effective 6 June 1978) 


Pursuant to Section 102 of the National Security Act of 1947, Executive Order 
12036, and Natiokal Security Council Intelligence Directives, and in order to ensure 
uniform protection\of classified foreign intelligence, and foreign counterintelligence ? 
involving sensitive Mtelligence sources and methods, processed and/or stored in 
Automated Data Procéssing (ADP) systems and networks, minimum security require- 
ments are hereby estabKshed. 


The diversity and complexity of such computer systems now in place in the 
Community and those already designed for future placement may not provide for 
compliance with the requirements of the directive in their entirety. Recognizing both 
the validity of the requirements and the difficulty involved in their application to 
currently installed and already designed ADP systems, the extent to which the 
exceptions to this Directive are applied to such systems is left to the determination of 
each National Foreign Intelligence Roard (NFIB) member in view of his ultimate 
responsibility for the protection of int&lligence information. 


1. Applicability 


This Directive shall apply to NFIB member agencies and all other United States 
Government departments and agencies whigh process and/or store intelligence 
information in ADP systems and networks. It shNl apply equally when ADP systems 
and networks are owned and/or operated by the Nnited States Government or by its 
contractors or consultants. 


2. Responsibilities 


Each NFIB member or his designee is responsible for Sasuring compliance by his 
respective organization and any other organization for \which he has security 
responsibility with the provisions of this Directive and the attached Computer 
Security Regulation. The NFIB member or his designee may delegate this responsibil- 
ity as he deems appropriate except only the NFIB member may\accredit an ADP 
system or network for operation in the Compartmented Mode. 


8. Policy 


A formal ADP security program shall be established and maintaine to ensure 
that intelligence information processed and/or stored by ADP systems and n&tworks is 


o 


1 Supersedes DCID 1/16, effective 18 May 1976. 

Foreign intelligence and foreign counterintelligence are used in this Directive as defined in Sec (on, 
Executive Order 12086, and as classified under the provisions of Executive Order #465& For the purpose of 
this Directive, the term “intelligence information” shall include both foreign intelligence and foretgn 
counterintelligence as so defined. 
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adequately protected. The minimum security requirements for the allowed modes of 
operation of ADP systems and networks are contained in the attached Computer 
Security Regulation. Additional ADP security measures and capabilities may be 
established if deemed appropriate. ADP systems involving foreign governments shall 
be addressed on a case-by-case basis by the NFIB members involved. 


4, Exceptions 
a. This Directive shall not apply to the ADP systems or networks that are used 
exclusively for telecommunications services. Such systems or networks are 
controlled by pertinent national policies and regulations. 


b. The NFIB member or his designee may temporarily exempt specific ADP 
systems under his jurisdiction from complete compliance with this Directive and 
attached Regulation when such compliance would significantly impair the 
execution of his mission. Chapter III of the attached Regulation governs when 
the ADP system being exempted is part of an ADP network as defined therein. 
An exemption shall be granted only when the NFIB member or his designee is 
confident that the other security measures in effect will adequately protect the 

intelligence information being processed. The NFIB member or his designee 
granting an exception shall strive for the earliest feasible attainment of complete 
compliance. No exception shall be granted which would allow personnel with less 
than a TOP SECRET clearance based on a background investigation to access an 


ADP system or network which contains Sensitive Compartmented Information 
(SCI).8 


c. Nothing in this Directive or the Computer Security Regulation shall 
supersede or augment the requirements on the control, use, and dissemination of 
Restricted Data, Formerly Restricted Data, or Communications Security 
(COMSEC) related material as established by or under existing statutes, direc- 
tives, or Presidential policy. 


3 The term “Sensitive Compartmented Information” as used in this Directive is intended to include. all 
information and materials bearing special Community controls indicating restricted handling within present 
and future Community intelligence collection programs and their end products for which Community 
systems of compartmentation have been or will be formally established. 


STANSFIELD TURNER 
Director of Central Intelligence 


Attachment: 
Computer Security Regulation 
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